Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that a digital identity…
Governance, Ownership & Risk

What are the signs that a digital identity strategy is not landing with users?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Governance, Ownership & Risk

Low recognition of the term, hesitation to use a single identity service, and continued reliance on insecure login methods are all warning signs. If people do not understand the value of the service, they may mistrust it or avoid it altogether. That creates weaker uptake, more friction, and less benefit from the programme.

What it looks like when users are not buying into the identity strategy

The first signal is usually social, not technical: people do not repeat the language of the programme, they ask what problem it solves, or they keep treating it as an IT initiative rather than a user-facing change. When a digital identity strategy is landing, users can describe the benefit in their own words, understand when to use it, and see it as simpler or safer than the old path.

A second signal is hesitation at the point of use. If users default to fallback processes, ask for exceptions, or avoid the new identity service for routine tasks, the strategy is not yet translating into confidence or habit. That gap matters because adoption depends on perceived usefulness, trust, and the amount of friction introduced into day-to-day access decisions.

A third signal is behavioural drift back to insecure methods. Continued reliance on passwords shared across systems, repeated use of legacy login paths, or manual workarounds suggests the new approach has not become the default operating model. In practice, that means the programme is failing to change real access behaviour, even if the underlying architecture looks sound on paper.

Why weak uptake matters beyond simple preference

Low adoption is not just a change-management issue. It can leave organisations with parallel login paths, fragmented enforcement, and weaker visibility into who is using which identity flow. If the strategy depends on a single service but users keep bypassing it, the security benefit is diluted and support costs rise at the same time.

This is where user perception becomes a control issue. If the identity experience feels opaque, slow, or punitive, users will work around it, and those workarounds often become the path of least resistance. The result is a strategy that exists formally but does not reshape behaviour consistently enough to deliver a measurable reduction in risk.

Adoption problems also tend to compound. Early confusion can become local culture, with teams teaching each other unofficial shortcuts. Once that pattern is established, the programme has to overcome not only usability issues but also habits, informal guidance, and the belief that the old method is still acceptable.

What practitioners should watch for in practice

Look for a mismatch between deployment metrics and real usage. A service can be technically launched, integrated, and approved while users still prefer old login methods or avoid the new option for sensitive workflows. The clearest evidence is not launch completion, it is whether users choose the new identity path when they have a real option.

It is also worth separating awareness from acceptance. Users may recognise the name of the service without trusting it enough to rely on it for daily access. That distinction matters because recognition alone can flatter programme reporting while concealment of hesitation continues underneath.

Where the service is meant to simplify access, repeated exception handling is a warning sign. Frequent requests for manual approval, support intervention, or alternate authentication usually indicate the strategy has not yet become intuitive enough to survive normal operational pressure.

Risk and Threat Considerations

When users do not adopt the intended identity path, organisations often retain insecure legacy methods longer than planned. That creates avoidable exposure because the weakest route is usually the one people keep using when the preferred route feels cumbersome or unfamiliar.

Failure mechanism: poor perceived value or usability drives bypass behaviour, which preserves parallel access paths and weakens the organisation’s ability to standardise authentication and access governance.

Impact: the programme delivers less security benefit than designed, creates more operational friction, and leaves a larger surface for account misuse, inconsistent policy enforcement, and support escalation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)User uptake depends on whether organizational users can and will use the intended login path.
IA-5 — Authenticator ManagementWeak adoption often shows up as continued use of old or insecure authenticators and login methods.
Recommendation — Standardize user authentication on the preferred identity service and remove avoidable fallback paths. Rotate out legacy authenticators and enforce a controlled authenticator lifecycle.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlThe question centers on whether identity controls are actually being used by the target population.
Recommendation — Measure real-world use of the approved identity flow and close gaps between policy and behavior.
ISO/IEC 27001:2022A.5.16 — Identity managementA landing identity strategy requires identities and their use to be governed consistently.
Recommendation — Align identity governance with user workflows so the approved path becomes the default.
NIST SP 800-63Digital Identity GuidelinesThe topic is about user acceptance of a digital identity approach and its authentication experience.
Recommendation — Use assurance and authenticator choices that users can adopt without excessive friction.

Practitioner Guidance

What to verify: Check whether users can explain the identity service in practical terms, not just whether they have been informed about it. If they cannot describe when to use it and why it is better than the old route, adoption is likely still superficial.

Decision rule: Treat repeated fallback use as a product and trust problem first, not as user resistance alone. If the new path is optional and people keep avoiding it, improve clarity, speed, and perceived value before tightening enforcement.

Practitioner takeaway: A digital identity strategy is landing only when users choose it willingly in routine work, not merely when the platform has been launched or communicated.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org